❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdayMain stream

β€˜Perfect 10’ Apple Supply Chain Bug β€” Millions of Apps at Risk of CocoaPods RCE

2 July 2024 at 12:30
Apple CEO Tim Cook, looking grim

Tim looks grim: 10 year old vulnerabilities in widely used dev tool include a CVSS 10.0 remote code execution bug.

The post β€˜Perfect 10’ Apple Supply Chain Bug β€” Millions of Apps at Risk of CocoaPods RCE appeared first on Security Boulevard.

3 million iOS and macOS apps were exposed to potent supply-chain attacks

1 July 2024 at 19:43
3 million iOS and macOS apps were exposed to potent supply-chain attacks

Enlarge (credit: Aurich Lawson)

Vulnerabilities that went undetected for a decade left thousands of macOS and iOS apps susceptible to supply-chain attacks. Hackers could have added malicious code compromising the security of millions or billions of people who installed them, researchers said Monday.

The vulnerabilities, which were fixed last October, resided in a β€œtrunk” server used to manage CocoaPods, a repository for open source Swift and Objective-C projects that roughly 3 million macOS and iOS apps depend on. When developers make changes to one of their β€œpods”—CocoaPods lingo for individual code packagesβ€”dependent apps typically incorporate them automatically through app updates, typically with no interaction required by end users.

Code injection vulnerabilities

β€œMany applications can access a user’s most sensitive information: credit card details, medical records, private materials, and more,” wrote researchers from EVA Information Security, the firm that discovered the vulnerability. β€œInjecting code into these applications could enable attackers to access this information for almost any malicious purpose imaginableβ€”ransomware, fraud, blackmail, corporate espionage… In the process, it could expose companies to major legal liabilities and reputational risk.”

Read 16 remaining paragraphs | Comments

❌
❌